WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token
class allows for code execution via its __destruct()
magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-l10n" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentyfour" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentythree" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentytwo" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-l10n" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentyfour" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentythree" }, { "binary_version": "6.4.3+dfsg1-1ubuntu1", "binary_name": "wordpress-theme-twentytwentytwo" } ] }